Skip to content

feat: workspace trust disclosure and PYTHINKER_CODE_TRUST_WORKSPACE - #337

Merged
elkaix merged 6 commits into
fix/session-behavior-defaultsfrom
feat/workspace-trust-disclosure
Oct 1, 2026
Merged

elkaix merged 6 commits into
fix/session-behavior-defaultsfrom
feat/workspace-trust-disclosure

Conversation

@elkaix

@elkaix elkaix commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Requirement or Bug

Make workspace trust transparent: a headless trust opt-out and a prompt that shows what trusting would activate.

Bug Reproduction Steps

N/A (features).

Root Cause

Headless runs had no way to pre-trust a workspace, and the trust prompt asked for a decision without showing what it would enable. Both addressed at the service layer.

Code Changes

  • New PYTHINKER_CODE_TRUST_WORKSPACE=1 env var trusts the current workspace for headless runs without answering the trust prompt; untrust reports the effective state.
  • The workspace trust prompt now lists the MCP servers, extra directories, and project instruction sources that trusting would activate, backed by a typed WorkspaceTrustDisclosureService.
  • SDK getWorkspaceTrustInfo gains origin, gatedAdditionalDirs, additionalDirSources, warnings, and instructionSources.
  • Docs: env-vars.md, mcp.md rows for the new variable and warning text.

Impact Scope

  • packages/agent-core-v2 (workspaceTrust domain, program wiring, trust prompt, mcpRegistry), packages/agent-gateway (env trust, untrust report), packages/node-sdk (trust info shape), CLI (cli/v2 MCP warning), docs.
  • Tests: env-trust, disclosure, trust-prompt, gateway, and SDK suites; full suite green locally.

Checklist

  • I have read the CONTRIBUTING document.
  • I have linked a related issue (external PRs: issue must have a maintainer's /approve). — No public issue; maintainer work.
  • I have added tests that prove my feature works.
  • Ran gen-changesets skill, or this PR needs no changeset.
  • Ran gen-docs skill, or this PR needs no doc update.

elkaix and others added 3 commits September 30, 2026 21:29
Headless runs can set the variable instead of answering the trust
prompt; the untrust route now reports the effective trust state.
The trust prompt and SDK trust info now disclose gated MCP servers with
their config origins, additional directory grants, and the project
instruction sources (AGENTS.md, skills, agent profiles) that load on
trust.
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

🗂️ Base branches to auto review (1)
  • main

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: PyModel/pythinker-code/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 9cc1ceda-4d1d-4c0c-99a2-4b3979aa9627

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
pnpm dlx https://pkg.pr.new/@pymodel/pythinker-code@bd5bea7
npx https://pkg.pr.new/@pymodel/pythinker-code@bd5bea7

commit: bd5bea7

pnpm audit reported 34 advisories (15 high) against the resolved tree:
undici, fast-uri, ip-address, dompurify, serialize-javascript,
markdown-it, brace-expansion, and electron. Raise the existing override
floors and add scoped ones (fast-uri pinned to ^3, brace-expansion per
major, markdown-it capped <15 because vitepress-plugin-llms deep-imports
markdown-it/lib/token.mjs, removed in 15). Bump electron 43.4.0 to
43.5.0 (GHSA high, patched >=43.5.0). Refresh the flake pnpmDeps hash
for the new lockfile.
check-artifacts.mjs pinned DOMPurify 3.4.14, ip-address 10.5.0,
fast-uri 3.1.5, and brace-expansion 1.1.18/2.1.4/5.0.9 as safe floors —
every one of them inside the advisory ranges fixed by the dependency
bump. Raise them to 3.4.16 / 10.7.1 / 3.1.8 / 1.1.21 / 2.1.7 / 5.0.12,
and make the Monaco resolved-version check a floor so future patch
bumps do not rebreak it.
@elkaix
elkaix merged commit ad9f9be into fix/session-behavior-defaults Oct 1, 2026
22 checks passed
@elkaix
elkaix deleted the feat/workspace-trust-disclosure branch October 1, 2026 03:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant